Endpoint Security Complete

  • 1.  Nmap Scanning Activity

    Posted Dec 13, 2022 05:24 PM
    Should we get worried? 

    [SID: 33939] Audit: Nmap Scanning Activity 2 attack detected but not blocked.

    1- why is not being blocked? 
    2- Nmap is very dangerous scan that shouldn't scan and not be blocked no?
    3- Should i block the remote IP address from the firewall to avoid future scan? or there's a better way to avoid Nmap scans period. 

    Thank you.


  • 2.  RE: Nmap Scanning Activity

    Posted Dec 14, 2022 04:20 AM
    It's either whitelisted in Host group rule, or ignored or allowed in the
    HIPS policy itself.





    Gregory A Anderson

    Linkedin Group and Profile <https: www.linkedin.com/groups/3776646/="">

    C 7209843292

    O 3032682216

    Skype 7204573585




  • 3.  RE: Nmap Scanning Activity

    Posted Dec 20, 2022 01:22 PM
    Can you please tell me how to block these malicious scans from happening in the future?  
    These are the ones i get:

    [SID: 32329] Audit: Malicious Scan Attempt 2 attack detected but not blocked. Application path: SYSTEM

    [SID: 33939] Audit: Nmap Scanning Activity 2 attack detected but not blocked. Application path: SYSTEM

    Thank you!


  • 4.  RE: Nmap Scanning Activity

    Broadcom Employee
    Posted Dec 20, 2022 01:30 PM
    It is an Audit detection. These are not blocked by default.  To block them you would go into your IPS policy, find these signatures, and change to block.

    ------------------------------
    John Owens
    Strategic Support Engineer | Symantec Endpoint Security Division (SES)
    Broadcom Software
    ------------------------------



  • 5.  RE: Nmap Scanning Activity

    Posted Dec 21, 2022 11:44 AM
    I apologize. but could you please provide the instructions for add/update the IPS policy?